

555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
WeX3sEVS
-1 OR 2+417-417-1=0+0+0+1 —
-1 OR 2+240-240-1=0+0+0+1
-1′ OR 2+934-934-1=0+0+0+1 —
-1′ OR 2+303-303-1=0+0+0+1 or ‘am3gWYLW’=’
-1″ OR 2+710-710-1=0+0+0+1 —
if(now()=sysdate(),sleep(15),0)
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
0″XOR(if(now()=sysdate(),sleep(15),0))XOR”Z
(select(0)from(select(sleep(15)))v)/*’+(select(0)from(select(sleep(15)))v)+’”+(select(0)from(select(sleep(15)))v)+”*/
-1; waitfor delay ‘0:0:15’ —
-1); waitfor delay ‘0:0:15’ —
1 waitfor delay ‘0:0:15’ —
-5 OR 133=(SELECT 133 FROM PG_SLEEP(15))–
-5) OR 529=(SELECT 529 FROM PG_SLEEP(15))–
-1)) OR 410=(SELECT 410 FROM PG_SLEEP(15))–
sztN9yJf’ OR 919=(SELECT 919 FROM PG_SLEEP(15))–
BeyusPf8′) OR 356=(SELECT 356 FROM PG_SLEEP(15))–
pK9pGZjF’)) OR 310=(SELECT 310 FROM PG_SLEEP(15))–
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
1′”
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
Leave a Reply to VyoMYfpV’)) OR 428=(SELECT 428 FROM PG_SLEEP(15))– Cancel reply